Sign InGet Started Free →
DPDP Act 2023 Compliant

DPDP Compliance at IvaBuddy

Indias Digital Personal Data Protection (DPDP) Act 2023 establishes how organizations must handle personal data. IvaBuddy was built with compliance as a foundation — not an afterthought. This page explains how we meet each key provision of the Act.

Independently audited · India-based data storage · All provisions covered

What Is the DPDP Act 2023?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's comprehensive data protection law. Passed by Parliament in August 2023, it governs how organizations (“Data Fiduciaries”) collect, store, process, and share personal data of Indian citizens (“Data Principals”).

The Act gives Indian citizens significant rights over their personal data and imposes obligations on organizations to handle data responsibly. Non-compliance can result in penalties up to ₹250 crore.

Key Rights Under DPDP Act

Right to access your personal data
Right to correction and erasure
Right to withdraw consent
Right to grievance redressal
Right to nominate a representative

How IvaBuddy Meets Each Provision

Section 4

Grounds for Processing Personal Data

COMPLIANT

IvaBuddy processes your personal data only for the purposes explicitly described in our Privacy Policy and with your informed consent at the time of registration. We do not process data for undisclosed or incompatible purposes.

Section 6

Notice to Data Principal

COMPLIANT

We provide clear notice of what data we collect, why we collect it, and how it is used — before collection. Our Privacy Policy is written in plain language and is accessible at any time.

Section 7

Consent Management

COMPLIANT

Your consent is sought through a clear, voluntary, and specific mechanism. You can withdraw consent at any time by contacting us or by deleting your account. Withdrawal of consent will result in cessation of processing (with limited exceptions for legal obligations).

Section 8

Obligations of Data Fiduciary

COMPLIANT

As a Data Fiduciary, IvaBuddy: (a) ensures accuracy of personal data; (b) implements security safeguards (AES-256 encryption, TLS 1.3, access controls); (c) deletes data after purpose is served or consent is withdrawn; (d) notifies the Data Protection Board and affected users within 72 hours of a data breach.

Section 11

Right to Access Information

COMPLIANT

You can request a summary of all personal data processed by IvaBuddy at any time by emailing privacy@ivabuddy.com. We respond within 30 days as required.

Section 12

Right to Correction and Erasure

COMPLIANT

You can update your personal information directly in your IvaBuddy account settings. To request complete erasure (right to be forgotten), contact privacy@ivabuddy.com. We will delete all personal data within 30 days, subject to legal retention requirements.

Section 13

Right to Grievance Redressal

COMPLIANT

We have appointed a Grievance Officer (details below) who responds to all complaints within 48 hours. Unresolved complaints can be escalated to the Data Protection Board of India.

Section 16

Processing Childrens Data

COMPLIANT

IvaBuddy does not knowingly collect personal data from children under 18 years of age without verifiable parental consent. Our service is intended for business use by adults.

Section 9

Processing of Personal Data Outside India

COMPLIANT

All IvaBuddy data is stored and processed exclusively in India (Mumbai and Delhi data centers). We do not transfer personal data outside India.

Security Measures Weve Implemented

AES-256 Encryption at Rest

All personal data stored in IvaBuddys systems is encrypted using AES-256, ensuring confidentiality in case of any unauthorized physical or logical access.

TLS 1.3 Encryption in Transit

All data transmitted between users and IvaBuddy servers uses TLS 1.3, the highest standard for transport security.

Access Controls & Audit Logs

Strict role-based access controls ensure only authorized personnel can access systems. All access is logged and audited.

Breach Response Plan

We maintain a documented incident response plan. In the event of a breach, affected users and the Data Protection Board are notified within 72 hours.

Data Minimization

We collect only the minimum personal data necessary to provide the service. We do not collect data beyond what is described in our Privacy Policy.

Data Retention Policy

Personal data is retained only as long as necessary for the stated purpose. Account data is deleted within 30 days of account deletion.

Grievance Officer & Data Principal Requests

Grievance Officer

Name
Lalit Kumar, Head of Privacy
Email
privacy@ivabuddy.com
Phone
+91 89305-36805 (Mon–Fri, 10 AM–6 PM IST)
Postal Address
IvaBuddy (Tech Codexae), Sector 63, Noida, Uttar Pradesh 201301, India
Response Time
Within 48 hours for acknowledgement; 30 days for resolution

Unresolved grievances may be escalated to the Data Protection Board of India once it is constituted under the DPDP Act 2023.

Submit a Request